CrestVPS

anonymous vps

Privacy infrastructure

For people whose threat model has a name.

What we would deploy

€25.13/mo

€35.9030% annual

Journalists, researchers and people operating under real pressure need infrastructure whose properties they can verify rather than trust. Diskless RAM-only mode leaves nothing on the drive to seize. LUKS2 with remote pre-boot unlock means the machine is useless without a passphrase we never see. Whonix Gateway images give a torified egress by default. Registration is an email address, and if you add a PGP key we cannot read our own correspondence with you in plaintext either.

Why this configuration

Reykjavik sits under some of the strongest source-protection statutes in Europe, Zurich under the revised Swiss FADP, and Chisinau outside EU instruments entirely. Pick the jurisdiction first, the plan second.

What we would deploy

PlanPULSE P2
vCPU4
RAM8 GB
Storage120 GB
ImageWhonix Gateway 17

Sizing

A RAM-only root holds the filesystem and everything that would otherwise be written. A minimal Debian or Alpine rootfs occupies 0.5-1.5 GB in tmpfs, before logs, package cache and application state. 4 GB is the floor, 8 GB is comfortable, and journald must be capped with RuntimeMaxUse or it will eventually consume the root. A Whonix gateway needs 1 core and 1 GB. Size the workstation behind it for its actual workload. LUKS costs nothing measurable with AES-NI.

Pre-boot unlock, done remotely

Full-disk encryption on a remote server is only useful if you never store the key on that server. The standard arrangement puts dropbear-ssh in the initramfs: the machine boots to a minimal stage, raises the network, and waits. You connect on a separate port, supply the passphrase, and the real root pivots in. Verify the initramfs host key out of band the first time, because that is the point at which a substituted stage would capture your passphrase. Combine this with a tmpfs root and the only durable state on the machine is the encrypted volume itself, unlocked only while you are watching.

Jurisdiction is the control; no-KYC is not

Signup at CrestVPS is an email address and no identity document is ever requested. That removes one link, not the whole chain. The server still occupies a rack in a named country, and CrestVPS answers valid legal process from that jurisdiction, with volumes published twice a year in a transparency report. Treat this as an engineering input. Choose the country for its actual law rather than its reputation, split key custody away from it, and put a Whonix gateway in front of anything where network-level correlation matters, so the workstation has no route except through Tor and no knowledge of its own public address.

What goes wrong

  • No unlock runbook. A LUKS volume needing pre-boot entry stays down after any unplanned reboot until a human types the passphrase. Monitor for the initramfs state specifically, and document who unlocks at 3am.
  • Swap on an unencrypted volume. A RAM-only root means nothing if the kernel pages application memory to plaintext disk. Use no swap at all, or encrypt it with a random key generated at boot.
  • Keeping keys in the same jurisdiction as the data. If the passphrase custodian and the server answer to the same legal process, the separation is decorative. Split them deliberately across countries.

Tune the machine

  • Storage and encryptionDiskless RAM-only mode · €22
  • Everything elseNo-log recursive resolver + DoH · Included
  • Addressing and transitIPv6 /48 delegation · €3